SilabRAT
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog, we deep-dive into SilabRAT and look at some of its interesting capabilities.
Techniques & procedures
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Execution
3 techniques
Execution
The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.
Persistence
3 techniques
Persistence
The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.
Privilege Escalation
5 techniques
Privilege Escalation
The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.
The author has written in forum posts future plans to implement fully customizable injection capabilities targeting Electron-based applications... injecting malicious code directly into their Electron processes.
SilabRAT utilizes an additional DLL named “APPB.dll” to employ the widely utilized technique of COM elevation to bypass ABE, where it decrypts the key by creating an instance via the GoogleChromeElevationService.
Stealth
1 technique
Stealth
Credential Access
4 techniques
Credential Access
These capabilities include keylogging functionality to capture user keystrokes...
Session hijacking is often more effective than password theft because it compromises an active authenticated session... Traditionally, session hijacking is achieved via stealing cookies. | Traditionally, session hijacking is achieved via stealing cookies. It is an old school technique where an attacker steals active session cookies and imports it into their own browser to impersonate the victim.
Beyond simply collecting cryptocurrency wallet data and stored credentials, the panel also advertises functionality that assists buyers in automatically cracking wallet passwords. This is achieved by leveraging passwords harvested from the victim’s browser data.
Lateral Movement
1 technique
Lateral Movement
Collection
2 techniques
Collection
Command and Control
1 technique
Command and Control
Other
1 technique
Other
The current implementation of the defense evasion technique is limited to straightforward bypasses targeting the Anti-Malware Scan Interface (AMSI). Specifically, the method employs a simplified approach to interfere with the AmsiScanBuffer and AmsiScanString functions...
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.